VYPR
High severity7.7NVD Advisory· Published Jun 22, 2026· Updated Jul 10, 2026

CVE-2026-42129

CVE-2026-42129

Description

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.